CVE Tools

The-eclipse-foundation

55 CVEs tracked since 2018. Since Jun 2018, none of them reached CISA KEV.

The-eclipse-foundation CVEs per month

Jun 2018 to Jul 2022. Point at a month, or focus the strip and use the arrow keys.
The-eclipse-foundation CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2018-0670
2018-07null or fewer
2018-0820
2018-09null or fewer
2018-1030
2018-11null or fewer
2018-12null or fewer
2019-01null or fewer
2019-0220
2019-03null or fewer
2019-04null or fewer
2019-05null or fewer
2019-06null or fewer
2019-0730
2019-08null or fewer
2019-0950
2019-10null or fewer
2019-11null or fewer
2019-12null or fewer
2020-01null or fewer
2020-02null or fewer
2020-03null or fewer
2020-04null or fewer
2020-05null or fewer
2020-06null or fewer
2020-07null or fewer
2020-08null or fewer
2020-09null or fewer
2020-1020
2020-1120
2020-12null or fewer
2021-0130
2021-0230
2021-03null or fewer
2021-0460
2021-05null or fewer
2021-0630
2021-0740
2021-08null or fewer
2021-0940
2021-10null or fewer
2021-11null or fewer
2021-12null or fewer
2022-01null or fewer
2022-02null or fewer
2022-03null or fewer
2022-04null or fewer
2022-05null or fewer
2022-06null or fewer
2022-0760

Products

The products that kept showing up in The-eclipse-foundation's monthly top three, with their CVEs summed over those months.

  1. Eclipse Jetty178 months
  2. Eclipse Openj985 months
  3. Eclipse Mosquitto63 months
  4. Eclipse Vert.x53 months
  5. Eclipse Theia32 months
  6. Eclipse Hono22 months
  7. Eclipse Omr21 month
  8. Eclipse Birt11 month
  9. Eclipse Californium11 month
  10. Eclipse Che11 month

Latest CVEs

The 15 most recently published vulnerabilities affecting The-eclipse-foundation.

  1. CVE-2023-0100In Eclipse BIRT, starting from version 2.6.2, the default configuration allowed to retrieve a report from the same host using an absolute HTTP path for the report parameter (e.g. __report=http://xy...8.8
  2. CVE-2022-2712In Eclipse GlassFish versions 5.1.0 to 6.2.5, there is a vulnerability in relative path traversal because it does not filter request path starting with './'. Successful exploitation could allow an ...6.5
  3. CVE-2022-3676In Eclipse Openj9 before version 0.35.0, interface calls can be inlined without a runtime type check. Malicious bytecode could make use of this inlining to access or modify memory via an incompatib...6.5
  4. CVE-2022-2838In Eclipse Sphinx™ before version 0.13.1, Apache Xerces XML Parser was used without disabling processing of referenced external entities allowing the injection of arbitrary definitions which is a...5.3
  5. CVE-2022-2576In Eclipse Californium version 2.0.0 to 2.7.2 and 3.0.0-3.5.0 a DTLS resumption handshake falls back to a DTLS full handshake on a parameter mismatch without using a HelloVerifyRequest. Especially,...7.5
  6. CVE-2021-41037In Eclipse p2, installable units are able to alter the Eclipse Platform installation and the local machine via touchpoints during installation. Those touchpoints can, for example, alter the command...10.0
  7. CVE-2021-41042In Eclipse Lyo versions 1.0.0 to 4.1.0, a TransformerFactory is initialized with the defaults that do not restrict DTD loading when working with RDF/XML. This allows an attacker to cause an externa...5.3
  8. CVE-2022-2191In Eclipse Jetty versions 10.0.0 thru 10.0.9, and 11.0.0 thru 11.0.9 versions, SslConnection does not release ByteBuffers from configured ByteBufferPool in case of error code paths.7.5
  9. CVE-2022-2047In Eclipse Jetty versions 9.4.0 thru 9.4.46, and 10.0.0 thru 10.0.9, and 11.0.0 thru 11.0.9 versions, the parsing of the authority segment of an http scheme URI, the Jetty HttpURI class improperly ...2.7
  10. CVE-2022-2048In Eclipse Jetty HTTP/2 server implementation, when encountering an invalid HTTP/2 request, the error handling has a bug that can wind up not properly cleaning up the active connections and associa...7.5
  11. CVE-2021-41041In Eclipse Openj9 before version 0.32.0, Java 8 & 11 fail to throw the exception captured during bytecode verification when verification is triggered by a MethodHandle invocation, allowing unverifi...5.3
  12. CVE-2021-41039In versions 1.6 to 2.0.11 of Eclipse Mosquitto, an MQTT v5 client connecting with a large number of user-property properties could cause excessive CPU usage, leading to a loss of performance and po...7.5
  13. CVE-2021-41038In versions of the @theia/plugin-ext component of Eclipse Theia prior to 1.18.0, Webview contents can be hijacked via postMessage().6.1
  14. CVE-2021-41036In versions prior to 1.1 of the Eclipse Paho MQTT C Client, the client does not check rem_len size in readpacket.9.8
  15. CVE-2021-41035In Eclipse Openj9 before version 0.29.0, the JVM does not throw IllegalAccessError for MethodHandles that invoke inaccessible interface methods.9.8

The record

Peak rank
#59 in Jun 2018
Busiest month shown
Jun 2018, 7 CVEs
Months with a KEV entry
0 since Jun 2018
Monthly snapshots
15 since 2018
The-eclipse-foundation's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store